HIGH
CVE-2023-4647
CVSS
7.5
Description
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which the projects API pagination can be skipped, potentially leading to DoS on certain instances.
Summary dbcve.org
GitLab's projects API has a pagination bypass vulnerability in versions 15.2 through 16.3.1. Attackers can skip pagination controls to request all projects in a single large request, potentially overwhelming server resources and causing denial of service.
Mitigation
Upgrade GitLab to version 16.1.6+, 16.2.6+, 16.3.2+ or later to patch the pagination bypass. Consider rate limiting API endpoints as an additional mitigation.
Weakness (CWE)
CWE-770
Resource Allocation Without Limits
EPSS Score
0.73%
Probability of exploitation in next 30 days
52.8th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.